Skip to content

[dev] [tofikwest] tofik/fix-dependabot-check-status#2205

Merged
tofikwest merged 2 commits intomainfrom
tofik/fix-dependabot-check-status
Mar 2, 2026
Merged

[dev] [tofikwest] tofik/fix-dependabot-check-status#2205
tofikwest merged 2 commits intomainfrom
tofik/fix-dependabot-check-status

Conversation

@github-actions
Copy link
Contributor

@github-actions github-actions bot commented Mar 2, 2026

This is an automated pull request to merge tofik/fix-dependabot-check-status into dev.
It was created by the [Auto Pull Request] action.

@vercel
Copy link

vercel bot commented Mar 2, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
app Ready Ready Preview, Comment Mar 2, 2026 7:47pm
1 Skipped Deployment
Project Deployment Actions Updated (UTC)
portal Skipped Skipped Mar 2, 2026 7:47pm

Request Review

@cursor
Copy link

cursor bot commented Mar 2, 2026

PR Summary

Medium Risk
Changes the pass/fail logic for the Dependabot check by switching to a different GitHub API endpoint and adding a new paused/unknown state, which can alter compliance results across repositories.

Overview
Updates the Dependabot check to stop relying on repo.security_and_analysis and instead query GitHub’s /repos/{owner}/{repo}/automated-security-fixes endpoint to determine security-updates status.

Adds explicit handling for paused (reported as pass with a different message) and unknown (reported as fail with guidance about missing admin access), and adjusts evidence to record dependabot_security_updates.status while still including the alert summary/counts when available.

Written by Cursor Bugbot for commit a4e6528. This will update automatically on new commits. Configure here.

Copy link

@cursor cursor bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

@vercel vercel bot temporarily deployed to Preview – portal March 2, 2026 19:45 Inactive
@tofikwest tofikwest merged commit 63b0053 into main Mar 2, 2026
10 checks passed
@tofikwest tofikwest deleted the tofik/fix-dependabot-check-status branch March 2, 2026 19:52
@claudfuen
Copy link
Contributor

🎉 This PR is included in version 1.87.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants